2007 CVE Vulnerabilities
6,580 CVEs published in 2007.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2007-3416 | — | — | 0.6% | Jun 26, 2007 | Multiple cross-site request forgery (CSRF) vulnerabilities in the administration of (1) polls, (2) profiles, (3) IP bans... |
| CVE-2007-3422 | — | — | 1.1% | Jun 26, 2007 | The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that... |
| CVE-2007-2798 | — | — | 7.5% | Jun 26, 2007 | Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other v... |
| CVE-2007-2442 | — | — | 11.4% | Jun 26, 2007 | The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote att... |
| CVE-2007-3410 | — | — | 36.1% | Jun 26, 2007 | Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPla... |
| CVE-2007-2443 | — | — | 3.5% | Jun 26, 2007 | Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (k... |
| CVE-2007-3407 | — | — | 8.4% | Jun 26, 2007 | Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) vi... |
| CVE-2007-3408 | — | — | 1.2% | Jun 26, 2007 | Multiple unspecified vulnerabilities in Dia before 0.96.1-6 have unspecified attack vectors and impact, probably involvi... |
| CVE-2007-3406 | — | — | 10.9% | Jun 26, 2007 | Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attacke... |
| CVE-2007-0773 | — | — | 0.3% | Jun 26, 2007 | The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service (kernel OOPS from nu... |
| CVE-2007-2951 | — | — | 3.2% | Jun 26, 2007 | The parseIrcUrl function in src/kvirc/kernel/kvi_ircurl.cpp in KVIrc 3.2.0 allows user-assisted remote attackers to exec... |
| CVE-2007-3104 | — | — | 0.4% | Jun 26, 2007 | The sysfs_readdir function in the Linux kernel 2.6, as used in Red Hat Enterprise Linux (RHEL) 4.5 and other distributio... |
| CVE-2007-3399 | — | — | 1.4% | Jun 26, 2007 | SQL injection vulnerability in include/get_userdata.php in Power Phlogger (PPhlogger) 2.2.5 and earlier allows remote at... |
| CVE-2007-3405 | — | — | 1.0% | Jun 26, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in defter_yaz.asp in Lebisoft zdefter 4.0 allow remote attackers to ... |
| CVE-2007-3404 | — | — | 2.9% | Jun 26, 2007 | Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files... |
| CVE-2007-3403 | — | — | 2.5% | Jun 26, 2007 | Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload a... |
| CVE-2007-3402 | — | — | 1.2% | Jun 26, 2007 | SQL injection vulnerability in index.php in pagetool 1.07 allows remote attackers to execute arbitrary SQL commands via ... |
| CVE-2007-3401 | — | — | 74.0% | Jun 26, 2007 | PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary... |
| CVE-2007-3400 | — | — | 3.6% | Jun 26, 2007 | The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.... |
| CVE-2007-3398 | — | — | 2.8% | Jun 26, 2007 | LiteWEB 2.7 allows remote attackers to cause a denial of service (hang) via a large number of requests for nonexistent p... |
| CVE-2007-3397 | — | — | 2.1% | Jun 26, 2007 | The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response da... |
| CVE-2007-3396 | — | — | 2.4% | Jun 26, 2007 | Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to injec... |
| CVE-2007-3394 | — | — | 2.1% | Jun 26, 2007 | Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the... |
| CVE-2007-2520 | — | — | 1.1% | Jun 26, 2007 | SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to e... |
| CVE-2007-3395 | — | — | — | Jun 26, 2007 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-2836. Reason: This candidate is a duplicate of... |
Check if your code is affected by 2007 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now